{"id":24365,"date":"2010-05-04T00:00:00","date_gmt":"2010-05-04T00:00:00","guid":{"rendered":"https:\/\/alienroad.com\/google-bilgi-bankasi\/do-know-evil\/"},"modified":"2010-05-04T00:00:00","modified_gmt":"2010-05-04T00:00:00","slug":"do-know-evil","status":"publish","type":"ar_kb","link":"https:\/\/alienroad.com\/google-bilgi-bankasi\/do-know-evil\/","title":{"rendered":"Do know evil"},"content":{"rendered":"<aside class=\"key-point\">It&#8217;s been a while since we published this blog post. Some of the information may be outdated (for example, some images may be missing, and some links may not work anymore).<\/aside>\n<p class=\"gargardate\">Tuesday, May 04, 2010<\/p>\n<p>\n  <i>Cross-posted on the<br \/>\n    <a href=\"https:\/\/googleonlinesecurity.blogspot.com\/2010\/05\/do-know-evil-web-application\" class=\"external-link\">Google Online Security Blog<\/a><br \/>\n  <\/i>\n<\/p>\n<aside class=\"note\">\n  UPDATE July 13: We have changed the name of the codelab application to Gruyere. The codelab is<br \/>\n  now located at<br \/>\n  <a href=\"https:\/\/google-gruyere.appspot.com\/\" class=\"external-link\">https:\/\/google-gruyere.appspot.com<\/a>.<br \/>\n<\/aside>\n<p>\n  We want Googlers to have a firm understanding of the threats our services face, as well as how to<br \/>\n  help protect against those threats. We work toward these goals in a variety of ways, including<br \/>\n  security training for new engineers, technical presentations about security, and other types of<br \/>\n  documentation. We also use codelabs&mdash;interactive programming tutorials that walk participants<br \/>\n  through specific programming tasks.\n<\/p>\n<p>\n  One codelab in particular teaches developers about common types of web application<br \/>\n  vulnerabilities. In the spirit of the thinking that &#8220;it takes a hacker to catch a hacker,&#8221; the<br \/>\n  codelab also demonstrates how an attacker could exploit such vulnerabilities.\n<\/p>\n<p>\n  We&#8217;re releasing this codelab, entitled &#8220;Web Application Exploits and Defenses,&#8221; today in<br \/>\n  coordination with<br \/>\n  <a href=\"https:\/\/code.google.com\/edu\" class=\"external-link\">Google Code University<\/a> and<br \/>\n  <a href=\"https:\/\/www.googlelabs.com\/\" class=\"external-link\">Google Labs<\/a><br \/>\n  to help software developers better recognize, fix, and avoid similar flaws in their own<br \/>\n  applications. The codelab is built around Gruyere, a small yet full-featured microblogging<br \/>\n  application designed to contain lots of security bugs. The vulnerabilities covered by the lab<br \/>\n  include cross-site scripting (XSS), cross-site request forgery (XSRF) and cross-site script<br \/>\n  inclusion (XSSI), as well as client-state manipulation, path traversal and AJAX and configuration<br \/>\n  vulnerabilities. It also shows how simple bugs can lead to information disclosure,<br \/>\n  denial-of-service and remote code execution.\n<\/p>\n<p>\n  The maxim, &#8220;given enough eyeballs, all bugs are shallow&#8221; is only true if the eyeballs know what to<br \/>\n  look for. To that end, the security bugs in Gruyere are real bugs&mdash;just like those in many<br \/>\n  other applications. The Gruyere source code is published under a Creative Commons license and is<br \/>\n  available for use in whitebox hacking exercises or in computer science classes covering security,<br \/>\n  software engineering or general software development.\n<\/p>\n<p>\n  To get started, visit<br \/>\n  <a href=\"https:\/\/google-gruyere.appspot.com\/\" class=\"external-link\">https:\/\/google-gruyere.appspot.com\/<\/a>.<br \/>\n  An instructor&#8217;s guide for using the codelab is now available on<br \/>\n  <a href=\"https:\/\/code.google.com\/edu\/security\/index\" class=\"external-link\">Google Code University<\/a>.\n<\/p>\n<p class=\"byline-author\">Posted by Bruce Leban, Software Engineer<\/p>\n","protected":false},"excerpt":{"rendered":"<p>It&#8217;s been a while since we published this blog post. Some of the information may be outdated (for example, some images may be missing, and some links may not work anymore). Tuesday, May 04, 2010 Cross-posted on the Google Online Security Blog UPDATE July 13: We have changed the name of the codelab application to [&hellip;]<\/p>\n","protected":false},"menu_order":85267,"template":"","meta":{"footnotes":""},"ar_kb_kategori":[665],"ar_kb_etiket":[],"class_list":["post-24365","ar_kb","type-ar_kb","status-publish","has-post-thumbnail","hentry","ar_kb_kategori-blog"],"_links":{"self":[{"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb\/24365","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb"}],"about":[{"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/types\/ar_kb"}],"version-history":[{"count":0,"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb\/24365\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/media\/26795"}],"wp:attachment":[{"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/media?parent=24365"}],"wp:term":[{"taxonomy":"ar_kb_kategori","embeddable":true,"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb_kategori?post=24365"},{"taxonomy":"ar_kb_etiket","embeddable":true,"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb_etiket?post=24365"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}